Autogram

Privacy Policy

Last updated 19 August 2026

Autogram ("we", "our", "us") operates autogram.co.in and the Autogram Instagram automation service. This policy explains what we collect, why we collect it, and how you get rid of it.

Information we collect

Account information

  • Email address, used for login and service notifications
  • Name, optional, used only for personalisation

Instagram data, via Meta's official API

  • Instagram username, user ID, and profile picture
  • Access tokens issued by Meta, encrypted at rest
  • Comments on your own posts and reels, read only to match your keywords
  • Delivery status of the messages we send on your behalf

Usage data

  • Number of DMs sent per campaign
  • Clicks on links we shorten and track for you
  • Dashboard activity logs

Payment information

Payments are processed by Razorpay. We never receive or store your card number, UPI ID, or netbanking credentials.

How we use your information

  • To match keywords in comments and deliver private replies
  • To show you analytics and campaign performance
  • To process payments and manage your subscription
  • To send you service-related notifications
  • To diagnose faults and improve the service

We do not use Meta-sourced data for advertising, profiling, or training machine learning models, and we never sell it.

Who we share it with

We do not sell or rent your personal information. We share only what is necessary with:

  • Meta / Instagram — to deliver DMs on your behalf through the official API
  • Razorpay — to process payments
  • Cloudflare — our infrastructure provider, where data is stored and processed
  • Law enforcement — only where we are legally required to

Storage and security

  • Data is stored on Cloudflare's infrastructure
  • Meta access tokens are encrypted at rest using AES-256-GCM
  • All data in transit is encrypted with TLS
  • We never ask for or store your Instagram password

How long we keep it

  • Account data — for as long as your account is active
  • Campaign and message logs — 90 days after a campaign ends
  • Webhook events — 30 days, for debugging
  • After deletion — everything is permanently removed within 30 days

Your rights

You can, at any time:

  • Access and export your data from the dashboard
  • Correct your details in dashboard settings
  • Disconnect your Instagram account
  • Delete everything — see data deletion

Meta platform data

We comply with Meta's Platform Terms and Developer Policies. We access only the data you explicitly authorise, use it solely for the purposes described above, and delete all Meta-sourced data when you disconnect your account.

Children

Autogram is not intended for anyone under 18, and we do not knowingly collect data from children.

Changes to this policy

We may update this policy. If a change is significant, we will tell you by email or in the dashboard before it takes effect.

Contact

Privacy queries
privacy@autogram.co.in
Postal address
Site No. 7-D, Export Knitwear Industrial Complex, Tiruppur, Tamil Nadu 641606, India